On Tue, Apr 11, 2000 at 01:29:49PM +1000, Steven Kerr wrote:
> I just need a pointer with IP Masq/IP Chains as I am confused
> regarding when these tools would be used.
> 
> Am I correct in saying that:
> 
> IP Masquarading allows hosts to project themselves onto another
> network (private or public) with a different IP address. This would
> normally be used with some sort of 'routing' software such as IP
> Chains

right enough

the routing software (ipchains) is just used to declare which traffic
streams will be masqueraded - the masquerading code (not ipchains)
does the real trickery

> IP Chains --> IP Forwarding is used to route /forward IP packets, say,
> across a firewall according to some rule sets that would be definable.

yes, ipchains is just an implementation of a "rule set".

ip forwarding itself is a fairly simple thing that doesn't necessarily
require the ability to firewall (ie. filter packets)

> So if that is the case, what kernel parameters would need to be set to
> masquarade a internal (private) LAN onto the internet via a Linux
> Server.

the minimum would be adding the forwarding rule:
"source = internal network  &  destination = external world
         -> masquerade me"

with ipchains, thats:
 ipchains -A forward -s 10.0.0.0/8 -j MASQ
(assuming your internal network is 10.0.0.0/8)

and then allowing traffic in and out:
 ipchains -P input ACCEPT
 ipchains -P output ACCEPT


since you are playing with the tables anyway, you will probably want
to be a lot more careful than that with your rules


if you are on a debian system, the "ipmasq" package does a very good
job of building these rules without you needing to do anything

-- 
 - Gus
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to